0ang3el Profile Banner
Mikhail Egorov Profile
Mikhail Egorov

@0ang3el

Followers
3K
Following
3K
Media
6
Statuses
471

Security researcher & bug hunter

Joined May 2016
Don't wanna be here? Send us removal request.
@0ang3el
Mikhail Egorov
4 years
RT @tinchoabbate: The MOST vulnerable contracts in all DeFi just got upgraded!. ⚙️ New testing env: Solidity 0.8 + Hardhat + Ethers.🌟 4 new….
0
131
0
@0ang3el
Mikhail Egorov
4 years
RT @S1r1u5_: Finally, here is the blog for the prototype pollution research we did. "A tale of making internet pollution free". - Exploiti….
0
329
0
@0ang3el
Mikhail Egorov
4 years
RT @chybeta: CVE-2021-40346 HAProxy HTTP Smuggling and ACL bypass. analysis.1. 2. demo: h….
0
106
0
@0ang3el
Mikhail Egorov
4 years
RT @emil_lerner: Here're slides from my talk at ZeroNights X! A 0-day for GhostScript 9.50, RCE exploit chain for ImageMagick with the defa….
0
129
0
@0ang3el
Mikhail Egorov
4 years
RT @orange_8361: A New Attack Surface on Microsoft Exchange! The series covers most of my Black Hat USA and DEFCON talks (with slides and v….
0
520
0
@0ang3el
Mikhail Egorov
4 years
RT @ptswarm: ✍️We would like to share with the community some uncommon but not unique cases from our experience. Let us know if you like th….
0
107
0
@0ang3el
Mikhail Egorov
4 years
RT @pdiscoveryio: [Release] 𝗣𝗗 𝗔𝗰𝘁𝗶𝗼𝗻𝘀 - Continuous reconnaissance and vulnerability assessment using GitHub Actions. Project:- https://t.….
0
134
0
@0ang3el
Mikhail Egorov
4 years
RT @infosec_au: Check out our blog post on Context Aware Content Discovery - we drop a tool (Kiterunner - https://t….
0
227
0
@0ang3el
Mikhail Egorov
4 years
RT @infosec_au: My colleague @seanyeoh wrote up his security research on H2C smuggling and the various cloud providers he successfully expl….
assetnote.io
0
115
0
@0ang3el
Mikhail Egorov
4 years
RT @emil_lerner: I got $15k #bugbounty for being able to execute a single shell command on my own laptop! That command was "man qemu-img".….
0
58
0
@0ang3el
Mikhail Egorov
4 years
RT @infosec_au: Thanks to everyone that tuned into my talk on Hacking IIS at #NahamCon2021. The slides for my talk are available here: http….
drive.google.com
0
200
0
@0ang3el
Mikhail Egorov
4 years
RT @orange_8361: I know there are lots of people waiting for the recent Microsoft Exchange pre-auth RCE on our side. This is a short adviso….
Tweet card summary image
proxylogon.com
ProxyLogon - The latest pre-authenticated Remote Code Execution vulnerability on Microsoft Exchange Server
0
433
0
@0ang3el
Mikhail Egorov
4 years
RT @PortSwigger: Blog post: mapping out Burp Suite's crawler. This is a deep dive into the crawler, which is at the heart of Burp Suite's c….
Tweet card summary image
portswigger.net
At the core of Burp Suite is Burp Scanner - a powerful tool designed to reduce the number of manual steps users have to take to discover vulnerabilities in their targets. Burp Scanner was first releas
0
72
0
@0ang3el
Mikhail Egorov
4 years
RT @emil_lerner: I'm releasing my tool that detects HTTP Request Smuggling opportunities that arise during HTTP/2 -> HTTP/1.1 conversion by….
Tweet card summary image
github.com
Contribute to neex/http2smugl development by creating an account on GitHub.
0
160
0
@0ang3el
Mikhail Egorov
4 years
RT @theBumbleSec: Just when you thought JSON was the one thing you could trust. My latest research on JSON interoperability vulnerabilities….
Tweet card summary image
bishopfox.com
Learn more about how the same JSON document can be parsed with different values across microservices, leading to a variety of potential security risks.
0
515
0
@0ang3el
Mikhail Egorov
4 years
RT @fransrosen: We did some fun tricks with nginx on bug bounties a while back, and made a post about out the configurations being vulnerab….
Tweet card summary image
labs.detectify.com
We found some interesting middleware misconfigurations and potential exploits affecting Nginx web servers, load balancers, and proxies.
0
245
0